analytics-engineering

Pass

Audited by Gen Agent Trust Hub on Apr 7, 2026

Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill instructs the agent to execute a shell command (ls) to inspect specific directory paths in the agent's environment (e.g., ~/.claude/skills/, ~/.agent/skills/) to identify other installed companion skills from the same ecosystem. This automated discovery occurs during the 'Companion check' section upon skill activation.
  • [PROMPT_INJECTION]: The instructions require the agent to adopt a specific response behavior upon activation, specifically starting its first response with the ๐Ÿงข emoji, which is an attempt to override standard agent behavior.
  • [COMMAND_EXECUTION]: The skill documentation suggests running installation commands like npx skills add to fetch and install additional skill components from an external source.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 7, 2026, 03:03 PM
Security Audit โ€” agent-trust-hub โ€” analytics-engineering